Sealevel

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 12
    Known Exploited: 0
    3
    Critical Level Threats
    6
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-21967

    An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to denial of service. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

    Last Modified: Apr 15, 2025
    Published: Apr 14, 2022

    CVE-2021-21962

    A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a man-in-the-middle attack in order to trigger this vulnerability.

    Last Modified: Apr 15, 2025
    Published: Feb 04, 2022

    CVE-2021-21968

    A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to arbitrary file overwrite. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

    Last Modified: Apr 15, 2025
    Published: Feb 04, 2022

    CVE-2021-21959

    A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality.

    Last Modified: Apr 15, 2025
    Published: Feb 04, 2022

    CVE-2021-21964

    A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

    Last Modified: Apr 15, 2025
    Published: Feb 04, 2022
    Items Per Page
    Sealevel Vulnerabilities & Security CVEs | CVE-DB